Content Security Policy violation: connect-src blocked when loading QuickSight assets

Hi,

I’m running into a persistent CSP-related error across the QuickSight experience (analysis, dashboards, open dashboard, etc.). The browser console reports:

“Connecting to ‘https://sourcemaps.prod.us-east-1.quicksight.aws.a2z.com/app/1.0.399539.0/esm/platform-libs.bundle.f4cc5c9de0543852.62.js.map’ violates the following Content Security Policy directive: ‘connect-src ‘self’ blob: https://.quicksight.aws.amazon.com wss://us-east-1.quicksight.aws.amazon.com https://.resources.maps.a2z.com https://maps.geo.us-east-1.amazonaws.com https://d233vg7hq6pih1.cloudfront.net https://d2an3pauscn6pz.cloudfront.net…..’”

Environment: [GoogleChrome/Windows]
QuickSight type: [QS Home Screen, Analysis, Dashboard, View Dashboard, Embedded iframe screen etc.]
Region: us-east-1
Frequency: Reproduces on every QS screen/workspace

I’ve 2 Quick Sight accounts and it’s happening on both.

Can you clarify what this error, why it’s happening and how we can resolve it?

Hi @Zerry00,

Is this a new error code that you recently started receiving; was this working in the past and then recently stopped working?

If it was working in the past, were there any changes made to your organization’s CSP?

While this old community post is more geared towards embedding, it discusses a similar error code being received:

I created my QS accounts almost three weeks ago and encountered this error during testing. So I guess it was there since creation but I just noticed it yesterday. I’ve gone through that post already but that’s more towards embedding and I am receiving these errors within QuickSight UI.

Hi @Zerry00,
I would suggest creating a support ticket then as the AWS team may be able to provide you with more direct assistance on account specific items: